public-webappsec@w3.org from May 2012 by subject

[Bug 17042] Last-Event-ID is not a simple header

[Bug 17205] New: graph.Facebook.com/ladybug2007

[cors] hey hey

[cors] hey hey (review of revised CORS Security Considerations et al)

[webappsec] Bay Area F2F Tomorrow and Thursday

[webappsec] ClearClick WAS2012 rv2

[webappsec] DRAFT agenda for F2F

[webappsec] for afternoon F2F discussion, proposed CSP 1.1 JSONP directive

[webappsec] Next F2F at TPAC 2012, Lyon, France, Oct

[webappsec] Schedule for TPAC 2012

[webappsec] Summary of anticlickjacking proposals

Agenda for May 8 Teleconference

An urge for CSP META tag in 1.0

Cancelled: May 22 Telecon

CfC: to stop work on From-Origin spec; deadline May 8

comments on Cross-Origin Resource Sharing (CORS) of 3-Apr-2012

correct CSP frame-src value for a scripted iframe src?

CSP 1.0

CSP 1.1

CSP 1.1 - capability advertisement and sandbox directive

CSP feature detection.

CSP transitivity and connect-src question

Draft minutes for May 2nd, 2012

Follow up on Test Jam

frame-options and the IETF websec WG

Keeping sandbox directive in CSP 1.0

Multiple Content-Security-Policy headers

proposed text for combining policies

Recent CSP edits

Reverted dd1f7a1cd84f

Rough sketch of directives for CSP 1.1

same-origin assertions in the DNS (Fwd: [apps-discuss] draft-sullivan-domain-origin-assert-00)

WebAppSec May F2F Minutes

When is the CORS Candidate Recommendation going to be published? [Was: Re: Cancelled: May 22 Telecon]

Last message date: Thursday, 31 May 2012 22:19:23 UTC